Compliance & Trust • India

Privacy Policy

Effective: [To be confirmed] Last updated: September 14, 2026 (Draft v1.0 — for legal review) Version: 1.0

Draft for business/legal review. Not legal advice. Requires review by qualified Indian counsel before publication or execution.

Developer Note:Draft for lawyer review under the Digital Personal Data Protection Act, 2023 (DPDP Act), DPDP Rules, 2025, IT Act 2000 & applicable TRAI/Telecom frameworks. Not legal advice. Requires review by qualified Indian counsel before publication. Do not claim certifications not held.

1. Introduction

Agilis Communication Services (“Agilis”, “we”, “us”) operates a cloud communications (CPaaS/CCaaS) and business software platform. This Policy describes how we collect, use, share and protect personal data when you use our website, platform, APIs and support. It is governed by Indian law, including the DPDP Act, 2023, the DPDP Rules, 2025, the Information Technology Act, 2000 and rules thereunder, and applicable TRAI/DoT telecom regulations (including TCCCPR 2018 as amended and DLT requirements). Capitalised terms follow the DPDP Act where applicable.

[LAWYER REVIEW: Confirm applicability of DPDP to Agilis as Data Fiduciary/Processor for each data category and whether Agilis qualifies as Significant Data Fiduciary.]

2. Scope & Roles

For Customer business data and end-user contact lists you upload (e.g., contact numbers, call lists, campaign data), you act as Data Fiduciary/Controller and we act as Data Processor/service provider, processing only on your documented instructions to provide the Services. For account, billing, support and website analytics data we collect directly from you, we act as Data Fiduciary. The scope includes digital personal data processed in India and, where the DPDP Act applies extra-territorially, processing in connection with offering services to Data Principals in India.

3. Information We Collect

  • Account & Business: name, work email, phone, company, GST/Tax IDs, billing address, KYC/PE/header/template identifiers where you provide them.
  • Contact & Configuration: business contacts you upload, DLT PE/header/template registrations, campaign configuration, consent records you maintain.
  • Communications Telemetry: call detail records (CDRs) — source/destination/routing numbers, timestamps, duration, delivery status, IP, session metadata; message delivery receipts; webhook events.
  • Content (where enabled): voice recordings, SMS/WhatsApp payloads processed strictly per your instructions — we do not sell or monetize end-user communications.
  • Support & API: tickets, logs, API activity, error traces, CRM integration data you authorize.
  • Website: cookies, device, browser, analytics (see Cookies section). We do not intentionally collect sensitive personal data beyond what is necessary for the Services.

[VERIFY: Remove any data type Agilis does not actually store (e.g., if recordings not stored, state “if enabled”).]

4. Telephony & Channel Data

Voice/SMS/WhatsApp channels are routed via telecom carriers, DLT platforms, and messaging providers (e.g., WhatsApp Business). Header/template registrations, sender consents and traffic are recorded on DLT per TCCCPR. CDRs and template metadata may be retained per statutory/regulatory or provider requirements. You are responsible for lawful acquisition of end-user consent, DND scrubbing, and DLT registration accuracy.

5. How We Use Data

We use personal data to: provide and secure the Services (routing, A2P delivery, webhooks, analytics, account management); authenticate and support; billing and fraud/abuse prevention; comply with law, TRAI/DoT/provider requirements and lawful requests; and improve the platform (aggregate/non-identifying where possible). We process voice/message content solely to route and deliver communications per your instructions.

7. Cookies & Analytics

We use strictly necessary cookies for login/session and security, functional cookies for preferences/timezone, and analytics/performance cookies for latency and documentation usage (see Cookie Policy at /cookie-policy). You can block cookies via browser settings, but essential session cookies are required for authenticated access. We do not use cookies to sell personal data.

8. Sharing & Subprocessors

We share personal data only as needed to provide the Services: with cloud infrastructure, telecom carriers, messaging platforms, numbering/DLT providers, payment processors and support tooling, each as subprocessors bound by confidentiality and security obligations. We disclose where required by law, TRAI/DoT orders, or to protect rights/safety, and we log disclosures where required. We publish or make available subprocessor information on request. We do not sell personal data.

[BUSINESS DECISION: Maintain a subprocessor list and DPA availability.]

9. Retention & Deletion

Retention periods depend on the data category and applicable law: account/billing per statutory and tax requirements; CDRs per TRAI/provider retention; recordings/campaign data per your plan retention/purge settings and Order. You may configure automated purges or request deletion of eligible Customer Data via privacy@agiliscommunications.com, subject to legal holds and provider logs. After termination, data is retained only for a reasonable retrieval window (target [30–90] days — [DECISION REQUIRED]) then deleted or anonymized except where retention is required by law. Backups, if any, are not guaranteed to be restorable; see Terms Section 13 — we do not guarantee zero loss. See Refund/Cancellation Policy for prepaid credit handling.

10. Security & Breach Notification

We implement reasonable security safeguards per DPDP Act Sec. 8(5) and IT Act reasonable security practices — e.g., TLS 1.3 in transit and AES-256 at rest where implemented (verify actual controls — do not claim undeployed certifications). Access is via RBAC and perimeter controls. In case of a personal data breach (unauthorised processing/disclosure/loss compromising confidentiality/integrity/availability — DPDP Sec. 2(u)), we will notify the Data Protection Board and affected Data Principals as required by Sec. 8(6) and DPDP Rules (including prescribed timelines and Board digital platform), and we will cooperate with you for downstream notification where you are Fiduciary. The Data Protection Board operates digitally; appeals lie to TDSAT (Appellate Tribunal).

11. Your Rights (Data Principals & Customers)

Under DPDP Act, Data Principals have rights to access, correction, update, erasure, nomination, and grievance redressal; we will respond within statutory timelines (DPDP Rules prescribe up to 90 days where applicable). Customers may exercise rights via privacy@agiliscommunications.com or designated DPO/contact. We will honor consent withdrawal and erasure subject to legal retention and provider log requirements. Significant Data Fiduciary enhanced rights/audits apply if notified.

12. Cross-Border Processing

Where cross-border transfer is necessary to provide the Services, we will process per DPDP Act and government-notified restrictions/localisation requirements for specified data categories, and via appropriate safeguards. [LAWYER REVIEW: Confirm whether any restricted category/localisation applies to Agilis data.]

13. Children

Services are for business use. We do not knowingly process children’s data for customer campaigns; customers must not upload children’s data without lawful basis and verifiable parental consent where required under DPDP Sec. 9.

14. Grievance Redressal & Contact

For privacy queries, rights requests, or grievances: privacy@agiliscommunications.com and legal@agiliscommunications.com — Customer-facing office: Office 206, EMCA House, 23 Ansari Road, Daryaganj, Delhi 110002, India — Phone (verified canonical): +91 98107 87931. [Registered/legal address may differ — GST shows A-70-B Patparganj Road, Delhi 110091; business to confirm; Grievance Officer name to be inserted per IT Rules/DPDP]. We will acknowledge and address grievances per DPDP/IT Act timelines. You may also approach the Data Protection Board digitally and appeal to TDSAT per DPDP Act.

[LEGAL REVIEW: Confirm Grievance Officer details, DPO designation, and publication as required under IT Rules/DPDP; verify customer-facing vs registered address distinction.]

15. Changes to this Policy

We may update this Policy to reflect legal, telecom or product changes. We will post the updated version with a new “Last updated” date and, where material, notify via email/console. Continued use after effective date constitutes acceptance as permitted by law.

Sources consulted: DPDP Act, 2023 (MeitY), DPDP Rules, 2025 (notified Nov 14, 2025; 18-month phased timeline, Board/TDSAT), IT Act, 2000 Sec. 43A/79, Telecommunications Act, 2023 (DoT), TRAI TCCCPR 2018 & 2025 Second Amendment (DLT, DCA, header/template, scrubbing, 140/1600 series, 30-min transactional limit, 7-day explicit consent validity). Requires lawyer confirmation.